Vulnerability record · CVE-2014-100005 · published 13 January 2015
CVE-2014-100005: D-Link DIR-600 router CSRF enables admin account creation and remote management
Dlink · Dir 600 Firmware
The D-Link DIR-600 (rev. Bx) with firmware before 2.17b02 is affected by multiple cross-site request forgery flaws in hedwig.cgi, pigwidgeon.cgi and diagnostic.php. An attacker who can lure an authenticated administrator into a crafted request can create an admin account, enable remote management, activate configuration settings or trigger a ping. The flaw matters because it gives an unauthenticated outsider a path to full administrative control of the router through the victim's browser session.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe device is end-of-life with no supported fix, the flaw is in CISA KEV, and EPSS is near the top percentile, though exploitation requires an authenticated admin session to be hijacked.
What it is
The D-Link DIR-600 (rev. Bx) with firmware before 2.17b02 is affected by multiple cross-site request forgery flaws in hedwig.cgi, pigwidgeon.cgi and diagnostic.php. An attacker who can lure an authenticated administrator into a crafted request can create an admin account, enable remote management, activate configuration settings or trigger a ping. The flaw matters because it gives an unauthenticated outsider a path to full administrative control of the router through the victim's browser session.
Impact
An attacker gains the ability to add an administrator account, turn on remote management and change active configuration, effectively taking over the device. That yields full control over routing, DNS and traffic passing through the router.
Attack surface
Reached over the adjacent network through the router's web management interface; the CVSS vector is AV:A/AC:L/PR:L/UI:N, and the description requires the victim administrator's authenticated session to be hijacked. No credentials are needed by the attacker, but the request must be delivered to a logged-in admin, which in practice depends on user interaction despite the UI:N vector.
Exploitation
CVE-2014-100005 is listed in CISA KEV (added 2024-05-16) and has an EPSS 30-day probability of 0.48146 (98.8th percentile), and references include an Exploit-tagged third-party writeup. No ransomware campaign use is documented.
What to do
- Retire and replace affected DIR-600 rev. Bx hardware, which D-Link and CISA state has reached end-of-life/end-of-service; no supported firmware fix is available.
- If the device cannot be replaced immediately, disable remote management and restrict administrative access to a trusted management network.
- Do not browse to untrusted sites or click untrusted links while logged into the router's admin interface, and log out when finished.
- Apply the vendor advisory SAP10018 guidance where any supported firmware path exists, and verify the running firmware version.
- Segment or block the router's management interface from general user networks to reduce CSRF reachability.
Detection
- Monitor router logs for unexpected creation of administrator accounts or changes to remote management settings.
- Alert on configuration activation (SETCFG,SAVE,ACTIVATE) or diagnostic ping actions originating from unexpected client IPs.
- Watch for HTTP requests to hedwig.cgi, pigwidgeon.cgi and diagnostic.php with unusual Referer or Origin headers.
- Audit for new admin logins or management sessions from addresses outside the expected administrative network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-100005 to the Known Exploited Vulnerabilities catalog on 16 May 2024 as "D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability". Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Federal deadline 6 June 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/ | ExploitThird Party Advisory |
| http://secunia.com/advisories/57304 | Broken Link |
| http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018 | PatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/91794 | Third Party AdvisoryVDB Entry |
| http://resources.infosecinstitute.com/csrf-unauthorized-remote-admin-access/ | ExploitThird Party Advisory |
| http://secunia.com/advisories/57304 | Broken Link |
| http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10018 | PatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/91794 | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-100005 | US Government Resource |
Track CVE-2014-100005 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-100005), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.